update filter image

This commit is contained in:
frack113
2022-10-31 19:40:07 +01:00
parent f27ddc8a0f
commit a1fef566bd
@@ -35,7 +35,11 @@ detection:
- '\rundll32.exe'
- '\inetsrv\iissetup.exe'
- '\inetsrv\appcmd.exe'
Image|contains: 'c:\windows\'
Image|startswith: 'C:\Windows\'
filter_programfiles:
Image|startswith:
- 'C:\Program Files\'
- 'C:\Program Files (x86)\'
filter_update:
CommandLine|startswith: 'C:\$WinREAgent\Scratch\'
CommandLine|contains: '\dismhost.exe {'